Appearance
GDPR Compliance
DRAFT — pending legal review. Not yet in effect. Do not rely on this page as a legal statement of Tarinoi's obligations until this notice is removed.
This page describes how Tarinoi Works Oy ("Tarinoi", "we"), incorporated in Finland, handles personal data under the EU General Data Protection Regulation (GDPR), what rights you have over your data, and how to exercise them.
For the general-purpose, plain-language privacy notice covering what data we collect and why (including third-party sign-in), see the Privacy Policy. This page is the authoritative source for GDPR-specific data-subject rights and retention detail; the two documents are meant to be read together and do not contradict each other.
1. Two roles: controller and processor
Tarinoi plays two different roles depending on what kind of data is involved, and it's important to understand which applies to you.
| Data | What it is | Tarinoi's role |
|---|---|---|
| Account data | Your email address, display name, organisation memberships, and any invitations you've sent | Controller — Tarinoi decides why and how this data is processed |
| Project content | Cards, dialogue, entities, and any other content created inside a Tarinoi project | Processor — the organisation (tenant) that owns the project is the controller; Tarinoi only stores and transmits it on their behalf |
In plain terms: Tarinoi is directly responsible for your account data — your login, your profile, which organisations you belong to. But once you or someone else starts writing content inside a project (dialogue, character names, story text), that content belongs to the organisation running the project, and Tarinoi has no visibility into whether it contains personal data about you or anyone else. If a project contains personal data about you (for example, a real person's name typed into a card), you should direct requests about that data to the organisation's administrator, not to Tarinoi — see §5 below.
This split exists because of how Tarinoi is built: project content is stored as opaque documents, authored under an internal account identifier with no name or email attached. Tarinoi's systems cannot read, search, or classify personal data inside project content — only the organisation that authored it can.
2. What account data Tarinoi holds, and for how long
As controller, Tarinoi holds:
- Your email address and display name
- Your account status (active, deactivated, etc.)
- Which organisations you're a member of, and your role in each
- Invitations you've sent to join an organisation
- Your sign-in identity (email, verification status, and which authentication methods you've set up), held in the identity system Tarinoi runs to manage sign-in
This data is retained for as long as your account exists. If you delete your account (§3.2), it is permanently removed within 30 days, except where deletion would need to be deferred to keep an organisation you own from being left without an owner (see §3.2).
3. Your rights, and how to exercise them
| Right | Applies to | How to exercise it |
|---|---|---|
| Access — see what data we hold about you | Account data | Use "Download my data" in My Profile → Account — see §3.1 |
| Rectification — correct inaccurate data | Account data | Edit your profile directly in My Profile |
| Erasure — have your data deleted | Account data | Delete your account in My Profile → Account — see §3.2 |
| Erasure — project content | Project content | Not something Tarinoi can fulfill directly — contact the organisation that owns the project |
| Portability — receive your data in a portable format | Account data | Same "Download my data" export as Access, above — delivered as a JSON file |
| Restriction of processing — pause processing without deleting | Account data | Deactivate your account in My Profile → Account — this halts sign-in and session access while retaining your data, and can be reversed at any time |
3.1 Download my data
From My Profile → Account, you can download a JSON file containing everything Tarinoi holds about you as controller: your account profile, your organisation memberships and roles, any invitations you've sent, and your sign-in identity (email, verification status, which authentication methods are enabled — not passwords or other credential secrets). This does not include project content — see §1.
Note: this download only includes data held by the Tarinoi service itself. If you've separately signed up for marketing communications (e.g. our newsletter), that data is held by our email provider and isn't accessible to the Tarinoi service — see §3.3.
3.2 Account deactivation and deletion
- Deactivate: signs you out of all devices and blocks sign-in until you reactivate. Fully reversible, and your data is retained as-is.
- Delete: schedules your account for permanent deletion 30 days from the request. You're signed out of all devices immediately, and you can cancel the deletion at any point before the 30 days elapse. Once the grace period passes, your account, organisation memberships, and Tarinoi identity are permanently removed.
Both actions are available directly in the app and require no support request. If you are the sole owner of an organisation, you'll need to either deactivate or delete the organisation, or promote another member to owner first — this is a safeguard against leaving an organisation with nobody able to administer it, not a way to prevent you from leaving.
3.3 Data held outside the Tarinoi service
Some personal data about you may exist outside the Tarinoi service itself — most notably, if you've subscribed to marketing communications such as our newsletter, that subscription is managed by our email provider (see §4), independently of your Tarinoi account. The service has no access to this data and it is not included in the "Download my data" export.
You can still exercise your GDPR rights over this data — access, rectification, erasure, or unsubscribing — by contacting us directly; we'll retrieve, export, or delete it on your behalf.
4. Sub-processors
Tarinoi uses the following sub-processors to provide the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Hosting, database, and infrastructure | europe-north1 (Finland) |
| Brevo | Transactional email (e.g. invitations, account notifications) | France |
5. Personal data inside project content
If you believe a Tarinoi project contains personal data about you — for example, your name appears in a card written by someone else — Tarinoi cannot identify, search, or act on this data on your behalf, since project content is opaque to us (§1). Please contact the administrator of the organisation that owns the project directly; they are the controller for that data and are responsible for responding to your request.
This document is a working draft pending review by legal counsel and is not yet published as Tarinoi's official GDPR statement.